Executive brief
Google Chrome on Android contains an uninitialized resource vulnerability in its GPU graphics processor. A remote attacker can exploit this flaw by tricking a user into visiting a crafted webpage, allowing them to read data outside the browser's security sandbox and potentially access sensitive information from the device or other applications.
Technical details
This vulnerability is classified as an uninitialized resource in the GPU component, which allows memory access outside the sandbox boundary. The attack vector is network-based, requiring only that a user visit a malicious HTML page—no authentication or additional user interaction beyond normal browsing is required. An attacker can leverage this flaw to read sensitive memory contents that should be isolated by the sandbox. The vulnerability affects Chrome on Android versions prior to 152.0.7977.65 and was patched in that release (August 25, 2026).
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65